Trojan:DOS/Alureon.E - Info To Clean

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cabldevil, Jan 26, 2012.

  1. cabldevil

    cabldevil Private E-2

    Hello. I just wanted to say thank you for the great information here in the MajorGeek Forums. I have a PC with this dreaded virus on it. I have reviewed all of the post and have now created my logs for your review.

    Unfortunately ComboFix will not complete (running from the desktop). I hope these logs will help in diagnosing my issue.

    Thank you again for the help and the resources.
     

    Attached Files:

    Last edited by a moderator: Jan 26, 2012
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Please download MIalt.bat and save it to your Desktop. Then right click on the Env.bat and select Run As Administrator. This will run reasonably fast and will add a log to C:\MGlogs.zip. Attach the updated MGlogs.zip file.

    Did you knowingly install the below items?

    O2 - BHO: ShopAtHome.com Toolbar - {66516A07-F617-488A-90CF-4E690CFB3C5F} - C:\Program Files\ShopAtHome\tbcore3U.dll
    O2 - BHO: Freecause Shopping BHO - {91917DC6-93B9-4E62-B2D6-D39C9618C418} - C:\Program Files\Shop to Win 4\ShoppingBHO.dll
    O2 - BHO: HelloWorldBHO - {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files\Common Files\Homepage Protection\HomepageProtection.dll
    O3 - Toolbar: ShopAtHome.com Toolbar - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Program Files\ShopAtHome\tbcore3U.dll
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost forgot!! Please also do the below.

    Now please also download MBRCheck to your desktop.


    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And after looking further into your logs, I'm betting that you are missing things from your Start Menu, All Programs, Desktop, Quick Launch etc which you have not mentioned yet.

    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Did that help with your missing items?
     
  5. cabldevil

    cabldevil Private E-2

    This is my neighbors computer and I do not know if he wanted them installed. regardless it is crap ware so my answer is no.

    Again thank you for your reply and I will do as you say as soon as I get home from work.
     
  6. cabldevil

    cabldevil Private E-2

    Actually the icons reappeared after I ran one of the tools but they are off color and there is nothing in the start menu. So you are correct again =)
     
  7. cabldevil

    cabldevil Private E-2

    Thank You Chaslang Icons are now visible from the start menu Logs to follow
     
  8. cabldevil

    cabldevil Private E-2

    OK here are my 2 logs thanks again I think we are getting close!
     

    Attached Files:

  9. cabldevil

    cabldevil Private E-2

    Just an update after those scans MSE still sees the dreaded virus from hell.....
     
  10. cabldevil

    cabldevil Private E-2

    Thank You Icons are now there but Alureon still looms =) I will wait for a reply before I start monkeying around with it.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes of course it does! I have not given you a fix for it yet which is why it is still there. ;) We needed more info first and we also need to restore your missing info.

    Do you have your Vista boot DVD so that we can use it to boot to the System Recovery Environment to repair your MBR? We will need to do this after we fix your infection which is in your partition table. A fake/infected partition has been added to your hard disk. See your partition list below. The one in red is the problem.
    Code:
    Partition Disk #0, Partition #0 
    Partition Size 366.35 GB (393,365,758,464 bytes) 
    Partition Starting Offset 32,256 bytes 
    [COLOR=red][B]Partition Disk #0, Partition #1 [/B][/COLOR]
    [B][COLOR=red]Partition Size 2.95 MB (3,088,384 bytes) [/COLOR][/B]
    [B][COLOR=red]Partition Starting Offset 400,085,360,640 bytes [/COLOR][/B]
    Partition Disk #0, Partition #2 
    Partition Size 6.26 GB (6,719,569,920 bytes) 
    Partition Starting Offset 393,365,790,720 bytes

    Also in preparation for our next steps, you have to make the below bootable CD containing G-Parted which we will use to remove the infected partition

    Just make the CD for now. Don't do anything else with it yet. I need to know if you have your Vista DVD or another way to boot to the Recovery Environment before we continue
     
  12. cabldevil

    cabldevil Private E-2

    Hey yesterday I burned the image and booted into gparted. I see the Partition that needs to be deleted and I have my repair disk.

    I cloned this disk just to practice on. On the clone disk I deleted the partition and the system booted clean in your post and many others with this virus you state to repair the Mbr with the vista disk. Why did my test hdd boot clean. Sorry for the question just wondering about the process. But I did not do this on the real hdd. I was waiting on your reply before I played with it. Thank you for your response
     
  13. cabldevil

    cabldevil Private E-2

    FYI nice to see a fellow NJ guy =) ty for the help ill hold tight till I hear from you (this is not a bump)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Because your infection had not yet made itself the active boot partition and thus simply deleting the infected partition worked okay. In many cases, these infections are making themselves the active boot partition and changing the MBR too. Thus are instructions cover this case too by having users repair the MBR and the boot process afterwards. If we did not give instructions for this and simply deleted the partition, many people would not know what to do afterwards when their PC would no longer boot into Windows.

    You should fix the real problem drive using G-Parted and if the real Windows boot partition is still the active partition, you may be okay and not have to do anything else.
    If the PC does not boot, you will have to boot into the System Recovery Environment and run the below commands

    • bootrec /fixmbr
    • bootrec /fixboot
    • exit
    After this is finished run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 30, 2012
  15. cabldevil

    cabldevil Private E-2

    OK here is the Log you requested. Thank you for the knowledge!
     

    Attached Files:

  16. cabldevil

    cabldevil Private E-2

    Sorry I did not run it with the bat file Here is the correct log files as you requested.

    Anyone following this thread please make sure you follow the directions given by the helper. Each infection is different!
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that took care of the infected partition. I notice the WMIC is not running. Did someone disable this on purpose?

    Is the PC having anymore malware problems?
     
  18. cabldevil

    cabldevil Private E-2

    No every scan comes up clean. I am not familiar with WMIC so I can say no it was not done by me or the user. I will search how to turn it on.


    Tank you for all the help!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The service may be disabled and stopped. Run the below newer version of MGtools and it may show us if the Windows Management Instrumentation service is stopped.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds